T08 · Insecure Dependencies
- Location
SKILL.md:35- Finding
Unpinned Third-Party Package Is Downloaded and Executed Through npx
- Content
View full analysis
Vulnerability Details
File Location:
SKILL.md:35-43
Vulnerability Type: Supply-chain risk caused by mutable dependency execution
Risk Level: HighVulnerable Code
json "command": "npx", "args": [ "chrome-devtools-mcp@latest", "--autoConnect" ]Technical Analysis
The recommended MCP configuration invokes
chrome-devtools-mcp@latestthroughnpx. Thelatesttag is mutable and does not identify a specific, previously reviewed release. Depending on the local npm configuration and cache state,npxcan download and execute the current package version when the OpenClaw gateway starts.The executed dependency is outside the audited project and receives browser-control capabilities through Chrome DevTools. Consequently, an upstream package compromise, malicious package publication, or unsafe future release could change the effective executable payload without any modification to this Skill.
This is an insecure dependency-loading pattern. The available evidence does not establish that the current upstream package is malicious, but the configuration creates a direct supply-chain execution path.
Attack Path
- The user adds the documented MCP server configuration to OpenClaw.
- The user restarts the OpenClaw gateway.
- OpenClaw invokes
npxwithchrome-devtools-mcp@latest. npxresolves the mutablelatesttag and may download the corresponding package.- A compromised or maliciously changed package executes locally as the user running OpenClaw.
- The package uses
--autoConnectto attach to the remote-debugging-enabled Chrome instance. - The malicious dependency can attempt to inspect or manipulate authenticated browser tabs and data available through the DevTools connection.
Impact Assessment
Successful exploitation could provide code execution with the privileges of the OpenClaw process. Because the package is configured as a browser-control MCP serv ...[truncated 335 chars]
- Remediation
View remediation
Remediation Suggestions
- Replace
chrome-devtools-mcp@latestwith an exact, reviewed version such aschrome-devtools-mcp@X.Y.Z. - Install the dependency in a controlled project with a committed lockfile instead of downloading it dynamically during gateway startup.
- Verify package provenance, publisher identity, release signatures, and integrity hashes before installation.
- Use an internal package mirror or approved artifact repository that retains reviewed versions.
- Configure automated dependency scanning and require security review before upgrading the pinned version.
- Run the MCP server under a dedicated, minimally privileged operating-system account or sandbox.
- Prevent unnecessary network access from the MCP process after installation where operationally feasible.
- Replace
